openicon.json with the hq block, 259 full-colour UI icons as WebP 64/128
and 111 brand SVGs in their owners' colours. The gallery's Simple/HQ
toggle appears on its own now that icons carry hq.
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* OpenEmoji catalog: browse and install by network
Reads platforms.json from the set: a network picker grouped by kind
(custom emoji, sticker packs, images to post), and for the chosen
network its verified limits, install steps, packs with sizes, Show (in
the grid) and Download (release assets), the grid narrowed to what its
bundles hold with each emoji's name on that network, and the detail
panel saying which pack holds it. A network that names what it is for
opens on it: X opens on country flags.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* OpenEmoji catalog: previews for 2,424 drawn glyphs
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replaces the 47-icon sample with the whole reference set: search by name,
alias or keyword; category chips with counts; UI/brand filter; SVG,
Nerd Font, Unicode or ASCII view (the Nerd Font view uses the official
symbols subset to the set's 349 glyphs, 38 KB woff2, MIT); size and
colour; a detail panel with all three glyphs and codepoints, trademark
notes, copy SVG / <img> / icon("key"), and downloads. Ready for the
optional HQ (full-colour) style: a Simple/HQ toggle appears once icons
carry an hq field. Filters live in the URL.
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
One openicon.json naming every icon (kebab-case keys, unique aliases,
shared keywords), 24x24 currentColor SVGs with a stated grid, and three
terminal glyphs per icon: a Nerd Font character with its codepoint and
glyph name, a Unicode symbol and a 1-4 character ASCII spelling, picked
nerd > unicode > ascii. Brand logos carry brand: true, a trademark note,
source and licence. made_by + W3C AI disclosure per set and per icon.
Mapping from Lucide, Tabler, Font Awesome, Nerd Fonts and Simple Icons.
Landing page shows 47 icons from the reference set (profullstack/openicon).
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* OpenEmoji catalog: every emoji in the reference set, with search and filters
/openemoji/catalog reads the set's openemoji.json (every Unicode emoji,
drawn or not) and filters by name and CLDR keyword, group, subgroup,
skin tone (keyboard-style swap), Emoji version and status, with sort,
tile size, URL-synced filters, paged rendering and a detail panel
(codepoints, tone family, copy, PNG/SVG downloads, keyword chips).
Spec: an entry without files is listed, not drawn.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* OpenEmoji catalog: reference set previews, first 206 glyphs
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
One openemoji.json that states coverage against a Unicode version, the
licence, and who or what drew the set (made_by plus the W3C AI disclosure
vocabulary), and glyphs named by fully-qualified codepoint sequence.
Custom emoji get x- keys with shortcodes; skin tones name their base;
rendered emoji keep the character as alt. Mapping from Mastodon, Slack,
Discord and CLDR.
Landing page shows 19 glyphs drawn by the reference implementation,
`emoji` in profullstack/cli-tools.
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The footer carries the three OpenWebring links (previous, ring, random,
next, with ?from=https://logicsrc.com/blog, the member URL the directory
holds), and /.well-known/openwebring.json says who makes the blog: both,
ai-generated, in the W3C AI Content Disclosure vocabulary the spec adopts.
Claude-Session: https://claude.ai/code/session_01XYae2mH3khdwiXUVzcVMDw
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* feat: add OpenFleet membership and CoinPay rental contracts
* Propose OpenWall broadcasts and direct messaging contracts
* release: prepare OpenFleet and OpenWall public contracts
* fix: use tested npm for compatible CLI installs
Lists LogicSRC on OpenAccess hubs (openaccess.logicsrc.com) so people can
link it with OAuth 2.1 + PKCE and it honours the shared
profullstack.com/all-access entitlement. The Ed25519 public key here is
the app's credential for reporting sales; the private half is in the
logicsrc teams vault openaccess-app-keys--prod. Scopes are empty for now:
the reserved openid, email and entitlements scopes need no listing.
Spec: https://logicsrc.com/openaccess
Claude-Session: https://claude.ai/code/session_01SWRffW4ifQPUrGXJtgYWMd
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
A failed install left the machine with no CLI at all. do_install ran
`rm -rf "$SRC_DIR"` and only then built; if the build failed, or the run
was interrupted, what remained was an unbuilt tree, a wrapper still
pointing at the dist/ that was never produced, and the previous run's
install.json still claiming success. Every later `logicsrc` invocation
died with MODULE_NOT_FOUND, and nothing said why.
That is what happened here: install.json dated 01:57, src/ replaced at
02:59 by a second run that did not finish.
Now the download, npm install and build all happen in a staging
directory, and $SRC_DIR is only touched once packages/cli/dist/index.js
actually exists -- the file the wrapper execs, so its absence is exactly
the failure the user would otherwise hit on their next command. Staging
sits inside $LOGICSRC_HOME so the swap is a rename on one filesystem
rather than a cross-device copy of node_modules, and the previous tree
is kept until the swap succeeds so a failed move can be undone.
Build output was going to /dev/null, so "build failed" carried no reason
at all. It is captured now, with the last 25 lines printed on failure and
the full log left on disk.
Also validates the commit id from the GitHub API before recording it:
anything that is not 40 hex characters is dropped rather than written
into install.json, which `logicsrc update` compares against.
Verified against a stubbed npm/curl in all three paths: a failing build
leaves the existing install running, a build that produces no artifact is
caught, and a clean install still swaps in and writes a correct manifest.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
The "Connect the CLI" card handed out:
LOGICSRC_API=https://app.logicsrc.com logicsrc login
logicsrc teams push <team> prod --env .env
logicsrc teams pull <team> prod --env .env
Two things are wrong with that, and both survived a release.
Since #109 addressed vaults as <team> <project> <env>, push and pull take
three positionals. The hint passes two, so pasting it exits with a missing-
argument error -- the card is not merely stale, it is broken.
The LOGICSRC_API prefix sets the variable to the value the CLI already
defaults to (DEFAULT_API_URL, #107), so on the hosted app it does nothing
while reading like a required step. It is now emitted only when the origin
is not the default, which is the case it exists for: self-hosting.
`--env .env` is dropped for the same reason -- it restates the option's own
default, and sitting next to the new <env> positional it made one flag and
one argument look like the same thing.
Same stale two-argument form fixed in the post-install hint (install.sh) and
the accept-invite message, and in the empty-vault-list prompt on the card.
CLI_HINT moves to src/lib/cli-hint.mjs so a test can assert on the rendered
commands without standing up express and the database, matching how the
other lib-level views are covered. The tests pin the argument count rather
than the prose: restyling the card stays free, dropping an argument does not.
apps/pwa: 13/13 pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
`update` was three hardcoded console.log lines: it printed 0.1.0 as both
current and latest, claimed "already up to date", and never checked or
installed anything. `--version` was hardcoded the same way.
A version comparison alone could not have worked either. install.sh ships
a tarball of the master branch, not a tagged release, and
packages/cli/package.json has been 0.1.0 since the repo began, so version
equality says "up to date" no matter how far master has moved. The commit
is the real signal.
- install.sh records ref/commit/version/installed_at to
$LOGICSRC_HOME/install.json. The sha comes from GitHub's
Accept: application/vnd.github.sha media type, so this needs no jq.
It is resolved before the download on purpose: if master moves
mid-install we under-report (a spurious update) rather than falsely
claim to be current.
- update compares the installed commit against the remote ref head,
falls back to version comparison for installs predating the manifest,
and reports why it reached its verdict instead of just asserting one.
--check reports without installing; otherwise it re-runs the installer.
- --version now reads the package's real version.
Verified against live GitHub in all three states: matching commit, stale
commit, and no manifest.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Adds apps/pwa: an Express + libSQL/Turso app that is now the home of team
credential sharing, with the moshcode-style auth stack ported and reskinned to
match logicsrc.com (light theme, Inter, green accent).
apps/pwa
- auth: email/password (scrypt), passkeys (WebAuthn), CoinPay OAuth, cookie
sessions, and lsk_ API keys for the CLI via a loopback OAuth-PKCE flow
(/cli/authorize + /cli/token). Ported from the moshcode PWA.
- credshare API (/api/credshare/*): teams, members, invites, vaults, sealed
grants, ciphertext secrets, audit — authed by session OR Bearer lsk_ key.
Zero-knowledge: only ciphertext + sealed vault keys + public keys stored.
- teams dashboard, accept-invite, and settings (API keys) pages, server-rendered
in the LogicSRC brand (lib/html.mjs).
- migrations (libSQL) 001_auth + 002_credshare, migrate-on-boot; Turso via
TURSO_DATABASE_URL / TURSO_AUTH_TOKEN, or a local file db for dev.
- trimmed moshcode-specific approvals/credits/push/deliver.
CLI
- `logicsrc login` now does browser loopback OAuth-PKCE against the app and
stores an lsk_ token (email-OTP removed); --token for CI. Client repointed.
Distribution
- install.sh (served at logicsrc.com/install.sh) installs the CLI from the
GitHub repo: tarball -> npm install -> `npm run build:cli` -> logicsrc wrapper.
- root build:cli builds only the CLI's workspace chain (skips web/api/next).
Cleanup
- removed the commandboard-api credshare backend (superseded by the PWA) and its
Supabase/Turso stores + libsql dep; commandboard-api tests green (40).
- removed the Next.js /teams page (the PWA is the web UI now).
Verified end-to-end: two accounts register on the PWA, mint lsk_ keys, CLI login
uploads identity keys, owner pushes an encrypted .env, teammate invited ->
accepted -> granted -> pulls the exact file. Server stores ciphertext only.
Full workspace build + tests green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add an autoblog webhook receiver and a Supabase-backed blog to logicsrc-web
(the app had no Supabase usage before).
- Migration: blog_posts table (RLS: public reads published, service-role
writes). Applied to the linked project.
- POST /api/webhooks/blog: verifies the Standard Webhooks signature against
BLOG_WEBHOOK_SECRET via @profullstack/autoblog verifyAndParse (no admin
user — shared secret only) and upserts the post by slug.
- /blog index + /blog/[slug] render published posts from the table.
- /blog/rss.xml and /sitemap.xml are now dynamic, generated from the table;
removed the static public/sitemap.xml and public/blog/rss.xml.
- BLOG_WEBHOOK_SECRET added to .env.example.
Verified end-to-end: a signed sample post delivered 200 and appeared in the
index, post page, RSS, and sitemap; build + typecheck pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>